XSS Vulnerability in Action View Tag Helpers for Ruby on Rails
CVE-2022-27777
6.1MEDIUM
Key Information:
- Vendor
Rubyonrails
- Vendor
- CVE Published:
- 26 May 2022
What is CVE-2022-27777?
A Cross-Site Scripting vulnerability exists in the Action View tag helpers of Ruby on Rails, specifically in versions greater than or equal to 5.2.0 and less than 5.2.0. This flaw allows attackers to inject malicious content into web applications by manipulating input into specified attributes. If an attacker can control specific input, they can potentially execute arbitrary script code in the context of the user's session, leading to the compromise of sensitive data and user impersonation.
Affected Version(s)
https://github.com/rails/rails 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1